Over 1,450 pfSense servers exposed to RCE attacks via bug chain
Roughly 1,450 pfSense instances exposed online are vulnerable to command injection and cross-site scripting flaws that, if chained, could enable...
Roughly 1,450 pfSense instances exposed online are vulnerable to command injection and cross-site scripting flaws that, if chained, could enable...
Miklos Daniel Brody, a cloud engineer, was sentenced to two years in prison and a restitution of $529,000 for wiping...
Sophos was forced to backport a security update for CVE-2022-3236 for end-of-life (EOL) firewall firmware versions after discovering hackers actively...
The Ukrainian government's military intelligence service says it hacked the Russian Federal Taxation Service (FNS), wiping the agency's database and...
Kyivstar, Ukraine's largest telecommunications service provider serving over 25 million mobile and home internet subscribers, has suffered a cyberattack impacting...
Microsoft warns that financially-motivated threat actors are using OAuth applications to automate BEC and phishing attacks, push spam, and deploy...
The Spanish police have arrested one of the alleged leaders of the 'Kelvin Security' hacking group, which is believed to...
Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was...
Valve has reportedly fixed an HTML injection flaw in CS2 that was heavily abused today to inject images into games...
The notorious North Korean hacking group known as Lazarus continues to exploit CVE-2021-44228, aka "Log4Shell," this time to deploy three...
A critical severity vulnerability in a WordPress plugin with more than 90,000 installs can let attackers gain remote code execution...
Cold storage and logistics giant Americold has confirmed that over 129,000 employees and their dependents had their personal information stolen...
Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a...
Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation....
A law enforcement operation is rumored to be behind an outage affecting ALPHV ransomware gang's websites over the last 30...
Elevation of privilege flaws are the most common vulnerability leveraged by corporate insiders when conducting unauthorized activities on networks, whether...
Kentucky health system Norton Healthcare has confirmed that a ransomware attack in May exposed personal information belonging to patients, employees,...
A new set of vulnerabilities in 5G modems by Qualcomm and MediaTek, collectively called "5Ghoul," impact 710 5G smartphone models...
Amazon's Customer Protection and Enforcement team has taken legal action against an underground store refund scheme that has resulted in...
Security researchers discovered a remote access trojan they named Krasue that is targeting Linux systems of telecommunications companies and managed...
Meta has announced that the immediate availability of end-to-end encryption for all chats and calls made through the Messenger app, as...
As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of...
Russian national Anatoly Legkodymov pleaded guilty to operating the Bitzlato cryptocurrency exchange that helped ransomware gangs and other cybercriminals launder...
Russian APT28 military hackers used Microsoft Outlook zero-day exploits to target multiple European NATO member countries, including a NATO Rapid...